actions-marketplace-validations/Scribe evidence verify

Verify compliance policies against evidence to ensure the integrity of supply chain.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Maintainedlast commit Dec 9, 2025
License
None

Pinned Snippet

workflow.ymlSHA-pinned
uses: actions-marketplace-validations/scribe-security_action-verify@2d486a137cb4076f916d081072a65e05e468fc0f # no releases — HEAD as of 2026-07-10

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
targetTarget object name format=[<image:tag>, <dir path>, <git url>] (Optional)yes
all-evidenceRun all evidence verification
attest-configAttestation config path
attest-defaultAttestation default config, options=[sigstore sigstore-github x509 x509-env kms pubkey]
attestationAttestation for target
base-imageBase image for the target
beautifyEnhance the output using ANSI and Unicode characters
bomCreate target SBOM evidence
bundlePolicy bundle uri/path (early-availability)
bundle-authBundle repository authentication info, [format: 'username:password']
bundle-branchBundle branch in the repository
bundle-commitBundle commit hash in the repository
bundle-depthBundle clone depth
bundle-tagBundle tag in the repository
cax509 CA Chain path
certx509 Cert path
common-nameDefault policy allowed common names
crlx509 CRL path
crl-full-chainEnable Full chain CRL verfication
depthGit clone depth
disable-crlDisable certificate revocation verificatoin
emailDefault policy allowed emails
exit-codeExit code to use when policy violations occur (-1 = ignore and keep original status, 0 = succeed regardless, 1-255 = fail with that code)
filter-purlFilter out purls by regex
filter-regexFilter out files by regex
filter-scopeFilter packages by scope
forceForce skip cache
formatPolicy Result Evidence format, options=[statement-sarif attest-sarif sarif ]
git-authGit repository authentication info, [format: 'username:password']
git-branchGit branch in the repository
git-commitGit commit hash in the repository
git-tagGit tag in the repository
initiativeInitiative configuration file path (early-availability)
initiative-idInitiative id
initiative-nameInitiative name
input-formatInput Evidence format, options=[attest-cyclonedx-json attest-slsa statement-slsa statement-cyclonedx-json statement-generic attest-generic ]
keyx509 Private key path
kmsProvide KMS key reference
mdOutput Initiative result markdown report file
ociEnable OCI store
oci-repoSelect OCI custom attestation repo
passPrivate key password
payloadpath of the decoded payload
platformSelect target platform, examples=windows/armv6, arm64 ..)
provenanceCreate target SLSA Provenance evidence
pubkeyPublic key path
public-keyPublic key path
ruleRule configuration file path (early-availability)
rule-argsPolicy arguments
rule-labelRun only rules with specified label
skip-bundleSkip bundle download
skip-confirmationSkip Sigstore Confirmation
skip-reportSkip Policy report stage
sourceSLSA Git repository source for target
source-asset-idSource asset id for SLSA Git repository source
source-asset-nameSource asset name for SLSA Git repository source
source-asset-platformSource asset platform for SLSA Git repository source
uriDefault policy allowed uris
cache-enableEnable local cache
configConfiguration file path
deliverableMark as deliverable, options=[true, false]
envEnvironment keys to include in evidence
gate-namePolicy Gate name
gate-typePolicy Gate type
inputInput Evidence target, format (\<parser>:\<file> or \<scheme>:\<name>:\<tag>)
labelAdd Custom labels
levelLog depth level, options=[panic fatal error warning info debug trace]
log-contextAttach context to all logs
log-fileOutput log to file
output-directoryOutput directory path./scribe/valint
output-fileOutput file name
pipeline-namePipeline name
predicate-typeCustom Predicate type (generic evidence format)
product-keyProduct Key
product-versionProduct Version
scribe-client-idScribe Client ID (deprecated)
scribe-client-secretScribe Client Token
scribe-disableDisable scribe client
scribe-enableEnable scribe client (deprecated)
scribe-urlScribe API Url
structuredEnable structured logger
timeoutTimeout duration
verboseLog verbosity level [-v,--verbose=1] = info, [-vv,--verbose=2] = debug
namedescription
OUTPUT_PATHevidence output file path